Version 1.2
Published and effective from: August 1, 2026
This Policy explains how personal data is processed when the Baal application, service and website are used. Baal is designed so that an Account is pseudonymous and message content remains end-to-end encrypted and available only on the Devices of conversation participants.
1. Data controller and contact details#
- The controller is SKY LEGAL TECHNOLOGY Spółka z ograniczoną odpowiedzialnością, with its registered office at ul. Generała Tadeusza Klimeckiego 9/2, 33-100 Tarnów, Poland, KRS 0000790701, NIP 8733271704 and REGON 383622561, referred to as the “Controller” or “Baal”.
- Privacy contact details:
- email: biuro@skylegaltech.com;
- post: ul. Generała Tadeusza Klimeckiego 9/2, 33-100 Tarnów, Poland.
- The Controller has not appointed a data protection officer. Privacy correspondence should be sent directly to the contact details above.
2. Privacy at a glance#
- An Account receives a random 256-bit technical AccountId, while the User chooses a separate public pseudonym. Baal does not require a real name, email address, telephone number, address book or payment details.
- Messages are encrypted and decrypted exclusively on Devices. The server receives Ciphertexts and has no decryption keys, escrow or “master key”.
- Conversation history and private keys remain in an encrypted local vault on Devices. An unread message remains until first reading and is then logically deleted after 12 hours. Baal creates no central archive or backup of the history.
- Baal does not use advertising, ad networks or marketing profiling. The website uses Google Analytics only after the visitor gives voluntary consent. The Application does not use external analytics or sign-in through Google, Apple or Facebook.
- Once Store integration is implemented, Apple and Google will participate in Application distribution and Subscription processing, but Baal will not receive card details or billing addresses.
3. Categories of data#
3.1. Account and Devices#
Baal processes:
- the current public pseudonym and signed public profile;
- a random 256-bit technical AccountId;
- identifiers of approved Devices;
- Account and Device public keys and the Account public-key history;
- Device certificates and unused KeyPackages;
- one-way hashes of retired pseudonyms and entries, checkpoints and witness signatures in the public append-only key-transparency log;
- the time at which the User declared that they were at least 18 years old, without a date of birth;
- Account settings and status needed to provide the Service.
The Device identifier, cryptographic keys and Device certificate are generated automatically by the Application. Private keys are never sent to the server.
3.2. Message delivery#
To deliver a message, the server temporarily processes:
- the Ciphertext;
- delivery addresses of the sender’s Device and recipient Devices and a random group identifier;
- frame type, time of acceptance, Ciphertext size, delivery status and acknowledgement;
- limited protocol data necessary to operate the queue and protect against abuse.
The server does not receive plaintext message content or keys capable of decrypting it.
3.3. Connection and security data#
- An IP address is technically visible while an internet connection is established. Baal and the web server do not record it in standard user logs. It is processed in memory for no more than 60 seconds to handle the connection and protect against abuse.
- VPS security logs may contain the IP address of an administrative login attempt, event time and authentication result.
- OVHcloud may process its own infrastructure logs in accordance with its policy and legal role.
3.4. Subscription data#
Baal may receive from Apple or Google only the data required to confirm entitlement to the Service:
- platform and product identifier;
- Subscription status and expiry date;
- last verification time;
- transaction identifier, receipt or signature required by the Store.
The Store identifier is encrypted at rest and logically separated from the communications identity. Baal does not receive card numbers, bank account data or billing addresses.
3.5. Contact, complaints and security reports#
If a person contacts us, makes a complaint or reports a vulnerability, we may process:
- the provided pseudonym or name;
- email address;
- Account or Device identifier, if supplied;
- subject, description, reproduction steps, impact assessment and correspondence;
- technical information voluntarily provided by the reporter;
- date, status and handling history of the matter.
Do not send private keys, passwords, another person’s data or unnecessary message content.
3.6. Website and cookies#
- The Baal website uses Google Analytics 4, measurement ID
G-8VGZB88XM5, only after the visitor gives voluntary consent. Before consent, the Google tag is not downloaded and no analytics data is sent to Google. - After consent, Google Analytics may process page views, page address and title, referrer, session time and statistics, approximate location and browser and Device information. Google uses the IP address when receiving data to determine approximate location and then discards it before it is logged in Google Analytics.
- Google Analytics may store
_gaand_ga_*cookies containing a pseudonymous client identifier. The_gacookie may remain for up to two years. Baal has disabled Google Signals and advertising personalisation and does not send form contents, message content, Account pseudonyms or communications identifiers to Google. - The analytics choice is stored locally in the browser. Consent can be changed or withdrawn at any time through the “Privacy settings” button. Rejecting analytics does not limit access to the website or Service.
- The vulnerability reporting form uses the necessary
BAALSECsession cookie and a one-time security token. These mechanisms protect the form against automated submissions and expire when the session ends or their technical validity period expires. - Disabling the necessary cookie may prevent the form from being submitted but does not limit access to the rest of the website.
4. Purposes and legal bases#
We process data for the following purposes:
- Creating and operating an Account, registering Devices, delivering Ciphertexts and confirming a Subscription — processing is necessary to enter into and perform a contract (Article 6(1)(b) GDPR).
- Managing paid access, complaints and conformity of the Service with the contract — performance of the contract and compliance with the Controller’s legal obligations (Article 6(1)(b) and (c) GDPR).
- Securing the Service, preventing abuse, protecting infrastructure and handling vulnerabilities — the Controller’s legitimate interest in maintaining the confidentiality, integrity, availability and resilience of the Service (Article 6(1)(f) GDPR).
- Responding to contact — performance of a contract or steps requested before entering into a contract and, in other cases, the legitimate interest in conducting correspondence (Article 6(1)(b) or (f) GDPR).
- Establishing, exercising or defending legal claims — the Controller’s legitimate interest (Article 6(1)(f) GDPR).
- Complying with law, final court decisions or binding requests from competent authorities — compliance with a legal obligation (Article 6(1)(c) GDPR).
- Measuring visits and improving the website through Google Analytics — the visitor’s voluntary consent (Article 6(1)(a) GDPR), which may be withdrawn at any time.
Consent is not used as the basis for processing necessary to provide the core Service. Website analytics consent is separate and voluntary; withdrawing it does not affect the lawfulness of processing before withdrawal.
5. How end-to-end encryption works#
- A message is encrypted before leaving the sender’s Device and decrypted only on an approved recipient Device.
- The server acts as a technical intermediary delivering a Ciphertext. It does not hold the cryptographic material required to read it.
- Because the Controller has no keys, it cannot:
- read conversation content;
- restore lost keys or history;
- reset an Account while preserving access to earlier correspondence;
- provide an authority or another person with decrypted content that it does not possess.
- Encryption does not protect a message displayed on an unlocked or compromised Device. Malware, an unauthorised future Application build, compromise of the update process or incorrect key verification represent separate risks. Baal therefore also protects update distribution, Device registration and key verification mechanisms.
- Baal provides a safety number and a public append-only key-transparency log requiring confirmation from two separate witnesses outside the main VPS. Inconsistent confirmations block contact initiation.
- End-to-end encryption does not hide all metadata. The AccountId, current public pseudonym, Device identifiers, sender and recipient delivery addresses, random group identifier, frame type and size, and delivery state may permit the Controller to infer part of the communications graph, but do not reveal message content.
6. Data recipients and providers#
Data may be disclosed only to the extent necessary:
- OVHcloud — as the provider of VPS hosting, networking and infrastructure. OVHcloud acts as a processor for data hosted on Baal’s instructions. It may act as a separate controller for its own technical data, customer account information and infrastructure logs.
- Apple and Google — as Store operators, Application distributors and entities handling payments and Subscriptions. They process Store accounts and payment data under their own policies and legal bases.
- Google Ireland Limited — as the provider of Google Analytics, solely in relation to website data processed after the visitor’s consent.
- Email providers, legal advisers, auditors or security specialists — where necessary to handle a report, dispute, incident or legal obligation and subject to appropriate safeguards.
- Courts, law enforcement, regulators or other competent authorities — only where a valid legal basis exists. End-to-end encryption and the absence of keys mean that the Controller cannot disclose decrypted content it does not possess.
Baal does not sell personal data or user lists.
7. Transfers outside the European Economic Area#
- Baal’s primary infrastructure is maintained by OVHcloud. The precise location and processing terms depend on the selected service and the agreement with OVHcloud.
- Apple, Google or their subprocessors may process Store-related data outside the EEA. Where this occurs, they use mechanisms required by the GDPR, such as an adequacy decision, standard contractual clauses or other appropriate safeguards.
- Google or its subprocessors may process Google Analytics data outside the EEA. Google states that, depending on the circumstances, it relies on mechanisms including adequacy decisions and standard contractual clauses.
- Details of the mechanisms used by Apple, Google and OVHcloud appear in their privacy policies. A person may also contact us for information about safeguards applying to data processed on Baal’s instructions.
8. Retention periods#
- Active Account profile and Devices: until the Account is deleted, the Service is permanently discontinued or the relevant record ceases to be necessary. The public AccountId anchor, Account public-key history, append-only key-transparency log and one-way hashes of retired pseudonyms remain indefinitely for the security purposes described in section 9.
- Age statement: for the life of the Account; the statement time also remains in the minimal deleted-Account anchor. No birth date is recorded.
- Undelivered Ciphertexts: no more than 24 hours after acceptance by the server. They are deleted immediately after delivery acknowledgement. A server restart may delete them earlier.
- Delivery data: only for the time required to operate the active queue and confirm delivery, after which it is deleted or anonymously aggregated where aggregation is necessary to maintain the Service.
- Local message history: an unread message remains in the Device’s encrypted vault until first reading. It is logically deleted 12 hours after first reading; reopening it does not extend that period. Logical deletion and key destruction do not guarantee immediate physical overwriting of flash storage.
- User connection IP address: not recorded by Baal or the web server in standard logs; processed in memory for no more than 60 seconds.
- VPS security logs: no more than seven days. These may include IP addresses of administrative login attempts.
- OVHcloud infrastructure logs: according to OVHcloud’s policy, for a service-dependent period of no more than 12 months. Baal cannot technically shorten a period determined independently by OVHcloud.
- Subscription data: for as long as required to confirm active entitlement, handle billing and complaints and then for any period required by law or necessary to establish, exercise or defend legal claims. Store identifiers are encrypted and separated from the communications identity.
- Vulnerability reports: until the report is closed, after which reporter data and details capable of reconstructing the vulnerability are deleted. Only anonymous statistics may be retained.
- Complaints and ordinary correspondence: for the time needed to handle the matter and then for any period required by law or necessary to defend legal claims.
- Data preserved under law: for the period required by the applicable provision, final decision or binding request of a competent authority.
- Google Analytics: analytics cookies may remain for up to two years, while Google Analytics data is retained according to the property retention settings and for the period necessary to analyse website statistics. The consent or refusal remains in the browser’s local storage until the choice is changed or website data is cleared.
Baal does not create backups of the Account database, Devices, public keys or Ciphertexts.
9. Account deletion and its effects#
- A User may initiate Account deletion in the Application settings.
- The operation removes from the server the active public Account profile, registered Devices and certificates, unused KeyPackages, pending Ciphertexts and delivery metadata.
- The public AccountId anchor and Account public-key history, entries in the append-only key-transparency log, the age-statement time and one-way hashes of retired pseudonyms remain indefinitely. This is necessary to prevent takeover of a deleted identity, reuse of a retired name and to verify log consistency. These data do not include message content or private keys.
- The Device performing the operation deletes local history, keys and identity. Other Account Devices may receive a deletion instruction if they are connected.
- Remote deletion cannot be guaranteed for a Device that is switched off, offline, lost or outside the User’s control.
- Account deletion does not remove message copies already delivered to other users’ Devices. The Controller has no remote access to them and cannot technically delete them. Copies are subject to local retention: until first reading and then for 12 hours after first reading.
- Account deletion does not cancel a Subscription in Apple App Store or Google Play. It must be cancelled separately in the Store.
- Data required by law or necessary for billing and legal claims may remain for the applicable period. This does not include a centrally held conversation archive or decryption keys.
10. Data subject rights#
Subject to the conditions in the GDPR, a person has the right to:
- access personal data and obtain a copy;
- rectify personal data;
- erase personal data;
- restrict processing;
- receive and transmit data processed by automated means on the basis of a contract;
- object to processing based on legitimate interests;
- withdraw consent where a specific processing activity is based on consent;
- lodge a complaint with the President of the Polish Personal Data Protection Office or another competent supervisory authority.
A request may be sent to biuro@skylegaltech.com. We may request information necessary to confirm that the requester controls the relevant Account or Device. Because the Account is pseudonymous and no central keys exist, we may not always be able to associate a person with an Account or retrieve or decrypt local data.
11. Whether data is required#
- Providing a public pseudonym and generating the random AccountId and technical data required to create an Account is voluntary, but the Service cannot be provided without it.
- An email address is required in the vulnerability reporting form to handle the report and reply. Fields identified as optional remain voluntary.
- Baal does not require data beyond what is needed for the selected feature.
- Consent to Google Analytics is voluntary. Refusing or withdrawing it does not limit access to the website or Service.
12. Automated decisions and profiling#
Baal does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect Users. It does not conduct advertising or marketing profiling.
13. Users under 18#
- Baal is intended only for persons aged 18 or over.
- Before creating an Account, a User must actively confirm that they are at least 18. We record only the time of the statement and do not collect a birth date or identity document.
- A person under 18 must not create an Account or use the Service. Information about an Account created by a minor may be sent to biuro@skylegaltech.com.
14. Data security#
- Measures include end-to-end encryption, the encrypted MobileVault, automatic locking when the Application enters the background or after two minutes of inactivity, separate Device keys, certificates, approval of new Devices, a safety number, a public key-transparency log, logical deletion of read messages after 12 hours, limited retention, data separation and administrative access controls.
- No system provides absolute security. Users should protect Devices with an access code, install updates, reject unknown Devices and verify keys in conversations requiring elevated trust.
- Vulnerabilities may be reported using the website form or by email to biuro@skylegaltech.com.
15. Planned notifications#
The current Baal version does not use push notifications. If Apple Push Notification Service or Firebase Cloud Messaging is enabled in the future, a notification will be an empty signal prompting the Application to check the mailbox and will not contain message content or the sender’s name. This Policy will be updated before the feature is enabled.
16. Legal duties concerning communications data#
- Baal is designed as a number-independent interpersonal communications service. Polish Electronic Communications Law distinguishes such a service from a telecommunications service.
- Baal does not conduct additional traffic data retention beyond what is technically required to provide the Service, subject to mandatory law, final court decisions and binding requests from competent authorities.
- The final classification of regulatory duties may depend on applicable law, regulatory practice and how the Service is provided. If a competent authority or a change in law requires specific data to be retained, this Policy will be updated and data will be processed only to the extent and for the period required.
- A duty relating to technical data would not create access to message content or provide the Controller with decryption keys.
17. Changes to this Policy#
- This Policy may be updated when features, providers, law, retention periods or security measures change.
- Users will be informed in the Application or on the website about a material change before it takes effect, unless an immediate change is necessary for legal or security reasons.
- The current version is available at baal-app.com/en/privacy.